File name:

bitcoin-0.1.0.rar

Full analysis: https://app.any.run/tasks/406b2a06-f351-4f3b-8965-918c56382173
Verdict: Malicious activity
Analysis date: April 23, 2024, 14:26:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32, flags: Solid
MD5:

91E2DFA2AF043EABBB38964CBF368500

SHA1:

EC9ED4CCBC990ECEB922FF0C4D71D1AD466990DD

SHA256:

8B17EB9A5707F2519DEFDA4CDF8D14FA1B8DEE630E11E6EF85FF9F5547555B56

SSDEEP:

98304:nti8wbXqzG7tKYMy40WqhtR6nIzU39UxlkjeN0WPeJURX7/uFnzNoWucjPmSCUsD:q3xuhRw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 324)
    • Actions looks like stealing of personal data

      • bitcoin.exe (PID: 3248)
      • bitcoin.exe (PID: 796)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 324)
  • INFO

    • Reads Microsoft Office registry keys

      • bitcoin.exe (PID: 3248)
      • bitcoin.exe (PID: 796)
    • Reads the computer name

      • bitcoin.exe (PID: 3248)
      • bitcoin.exe (PID: 796)
    • Reads Environment values

      • bitcoin.exe (PID: 3248)
      • bitcoin.exe (PID: 796)
    • Reads the machine GUID from the registry

      • bitcoin.exe (PID: 3248)
      • bitcoin.exe (PID: 796)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 324)
    • Creates files or folders in the user directory

      • bitcoin.exe (PID: 3248)
    • Manual execution by a user

      • taskmgr.exe (PID: 548)
      • bitcoin.exe (PID: 796)
    • Checks supported languages

      • bitcoin.exe (PID: 796)
      • bitcoin.exe (PID: 3248)
    • Create files in a temporary directory

      • bitcoin.exe (PID: 3248)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 1000
UncompressedSize: 2693
OperatingSystem: Win32
ModifyDate: 2009:01:07 01:00:00
PackingMethod: Best Compression
ArchivedFileName: src\makefile
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
4
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe bitcoin.exe taskmgr.exe no specs bitcoin.exe

Process information

PID
CMD
Path
Indicators
Parent process
324"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\bitcoin-0.1.0.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
548"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
796"C:\Users\admin\Desktop\bitcoin.exe" C:\Users\admin\Desktop\bitcoin.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\bitcoin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\libeay32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3248"C:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\bitcoin.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\bitcoin.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3489660927
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa324.22218\bitcoin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rar$exa324.22218\libeay32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
Total events
7 604
Read events
7 573
Write events
31
Delete events
0

Modification events

(PID) Process:(324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(324) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\bitcoin-0.1.0.rar
(PID) Process:(324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
6
Suspicious files
15
Text files
84
Unknown types
0

Dropped files

PID
Process
Filename
Type
324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\rc\addressbook16mask.bmpbinary
MD5:D2D7A8E2781E93BEBE3509DE3DAF83B1
SHA256:A22071608F7E38B4B18F69D87123F6D7429710E8EA7B5370F1C86B14193FBF50
324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\rc\send16.bmpimage
MD5:0AA745307D8E91352C23BA425BF082D3
SHA256:553D3EE80472F791D1DA36600F534B702AF159F98C54191031847F283F70715E
324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\irc.cpptext
MD5:E41E8555D0B853821EC4D3AB0668E6EF
SHA256:1713317EA55C88D5A0A61E2B72845D273EB8CA9A409B6A567FD5090EB2D5A2FF
324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\rc\send20mask.bmpimage
MD5:D96799FAD965ABB565A31E77CF6A203E
SHA256:EFB5D66BB902A281406D3B5CC4092008DBDCB5C77B298C06B3EF79E8BFA16160
324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\rc\addressbook20.bmpimage
MD5:5A0474014AB8CEB34007A8615BD36A08
SHA256:76FE6679DA5C4D9FD763084A19D1D0CF0EB3FB78F8799BA064E912D1AB4B0B10
324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\rc\send16masknoshadow.bmpimage
MD5:96884C7DA51CB665BD5EACD570E412C7
SHA256:08C7EFFF95FC90A198DD190E50761281CBFAB42E17F064B7146D952D94601749
324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\net.cpptext
MD5:040A5FD6BD38B862B85B39D5743E00F4
SHA256:FBAF9B912F7FEDD87C8A1F1E232CB04DD567E41007ABE900772579CF1E29DCBE
324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\ui.cpptext
MD5:EBD8CB8ADB86AE3D8CA5EB86A69DB992
SHA256:BEC80418526C9FE45F3B83C99C0A708363942DF271D3F048C18FEC6EBFF8FA63
324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\main.cpptext
MD5:E04B403D08684267AD12CA71D244BFD4
SHA256:C89F44185DF7FF5D68342E5F533AE1282D5CF1259306D14C1C79315E973E0E1C
324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\rc\send16mask.bmpimage
MD5:241B85366C2F6CC0F244C261DF865574
SHA256:7297C773DA79FC0EF61799B3B698274FD4F6D74D3C3A727AD6DFF41358968191
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3248
bitcoin.exe
72.233.89.199:80
RMH-14
US
unknown
796
bitcoin.exe
72.233.89.199:80
RMH-14
US
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
Process
Message
bitcoin.exe
sending: version (46 bytes)
bitcoin.exe
RandAddSeed() got 154720 bytes of performance data
bitcoin.exe
bitcoin.exe
bitcoin.exe
Bitcoin CMyApp::OnInit()
bitcoin.exe
bitcoin.exe
bitcoin.exe
bitcoin.exe
bitcoin.exe